Presshousesupport@presshouse.app

Presshouse Data Processing Addendum

Last updated: October 3, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service (or any written agreement) between you, the customer ("Customer"), and Intentionally Creative LLC ("Presshouse", "we") for the Presshouse service. It applies whenever we process personal data on Customer's behalf. It needs no signature; if your organization needs a countersigned copy, email support@presshouse.app.

1. Definitions

"Data protection law" means every privacy and data protection law that applies to the processing, including the EU and UK General Data Protection Regulations (GDPR), the Swiss Federal Act on Data Protection, the California Consumer Privacy Act (CCPA) and other US state privacy laws. "Customer personal data" means personal data that Customer or its users put into Presshouse, or that Presshouse collects for Customer or from visitors to websites Customer publishes. "Controller", "processor", "data subject", "personal data breach" and "processing" have the meanings given in the GDPR; "service provider" and "business" have the meanings given in the CCPA.

2. Roles

Customer is the controller (or "business") of Customer personal data, and we are its processor (or "service provider"). We process Customer personal data only to provide, support and secure Presshouse for Customer, on Customer's documented instructions. The Terms of Service, Customer's configuration of Presshouse and this DPA are those instructions. We tell Customer if we believe an instruction breaks data protection law.

3. What we process

Subject matter and duration Providing Presshouse, for as long as Customer uses it and the return or deletion period after
Nature and purpose Hosting, storing, organizing, analyzing and transmitting data, including with AI features, to deliver the service Customer configures
Data subjects Customer's team members; visitors to websites Customer publishes; people who send forms on those websites
Personal data Contact details of team members; form submissions and website visit data from visitors to Customer's sites
Special categories Not intended. Customer will not put special category data, government ID numbers or payment card numbers into Presshouse except through the payment provider's own forms

4. Our commitments

We will:

5. Customer's commitments

Customer is responsible for having a lawful basis for the processing, for giving people the notices and obtaining the consents the law requires (including consent to receive texts and calls), and for the accuracy of the data it provides.

6. Subprocessors

Customer authorizes us to use the subprocessors listed in Service Providers and Subprocessors. We bind each one by contract to data protection terms that protect Customer personal data at least as well as this DPA, and we remain responsible for them. We will give at least 30 days' notice of a new subprocessor by updating that page and, for customers who ask to be notified, by email. Customer may object on reasonable data protection grounds; if we cannot address the objection, Customer may end the affected service and receive a refund of prepaid fees for it.

7. International transfers

Customer personal data may be processed in the United States and Germany, and by subprocessors in the countries listed. Where data protection law requires a transfer safeguard for data from the European Economic Area, the UK or Switzerland, the parties agree to the European Commission's Standard Contractual Clauses (Module 2, controller to processor, or Module 3 where Customer is itself a processor), with the UK International Data Transfer Addendum and Swiss amendments where they apply. For those clauses: Customer is the data exporter, we are the data importer, the optional docking clause applies, the supervisory authority is the one competent for Customer, the governing law and courts are those of Ireland, and Annexes I to III are completed by sections 3, 6 and 9 of this DPA.

8. Audits

Once a year, or after a breach, Customer may ask us written questions about our compliance, and we will answer them. If those answers are not enough, Customer may audit, at its own cost, with at least 30 days' notice, during business hours, under confidentiality and in a way that does not reveal other customers' data.

9. Security measures

10. Order of precedence and liability

If this DPA conflicts with the Terms of Service about personal data, this DPA governs. Liability under this DPA is subject to the limits in the Terms of Service, except where data protection law does not allow it.

Contact

We answer every message, normally within a few working days.